İçeriğe atla
Noroxi

trustwave kayıtları

trustwave üreticisine ait 18 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%61,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

18 kayıt
  • CVE-2017-18001
    43Planlayın

    Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorize

    KritikCVSS 9,8Kavram kanıtıEPSS %14

    trustwave · secure web gateway31 Ara 2017

  • CVE-2014-2727
    40Planlayın

    The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

    KritikCVSS 9,8İstismar yokEPSS %2

    trustwave · mailmarshal19 Şub 2020

  • CVE-2013-1915
    31İzleyin

    ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of servi

    YüksekCVSS 7,5İstismar yokEPSS %4

    trustwave · modsecurity25 Nis 2013

  • CVE-2021-42717
    31İzleyin

    ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects.

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    owasp · modsecurity7 Ara 2021

  • CVE-2025-27110
    31İzleyin

    Libmodsecurity3 has possible bypass of encoded HTML entities

    YüksekCVSS 7,9İstismar yokEPSS %0

    trustwave · modsecurity25 Şub 2025

  • CVE-2022-48279
    30İzleyin

    In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firew

    YüksekCVSS 7,5İstismar yokEPSS %1

    owasp · modsecurity20 Oca 2023

  • CVE-2023-24021
    30İzleyin

    Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over

    YüksekCVSS 7,5İstismar yokEPSS %1

    trustwave · modsecurity20 Oca 2023

  • CVE-2024-46292
    30İzleyin

    A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name para

    YüksekCVSS 7,5İstismar yokEPSS %1

    trustwave · modsecurity9 Eki 2024

  • CVE-2025-47947
    30İzleyin

    ModSecurity Has Possible DoS Vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    trustwave · modsecurity21 May 2025

  • CVE-2009-1902
    24İzleyin

    The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapo

    OrtaCVSS 5,0Kavram kanıtıEPSS %14

    trustwave · modsecurity3 Haz 2009

  • CVE-2013-2765
    24İzleyin

    The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereferenc

    OrtaCVSS 5,0Kavram kanıtıEPSS %14

    apache · http server15 Tem 2013

  • CVE-2012-4528
    24İzleyin

    The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to

    OrtaCVSS 5,0Kavram kanıtıEPSS %13

    trustwave · modsecurity28 Ara 2012

  • CVE-2013-5705
    21İzleyin

    apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalize

    OrtaCVSS 5,0İstismar yokEPSS %3

    trustwave · modsecurity15 Nis 2014

  • CVE-2011-1906
    20İzleyin

    Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier f

    OrtaCVSS 5,0İstismar yokEPSS %1

    trustwave · webdefend5 May 2011

  • CVE-2011-0756
    20İzleyin

    The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote att

    OrtaCVSS 5,0İstismar yokEPSS %1

    trustwave · webdefend4 May 2011

  • CVE-2012-2751
    18İzleyin

    ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in th

    OrtaCVSS 4,3İstismar yokEPSS %3

    trustwave · modsecurity22 Tem 2012

  • CVE-2009-1903
    18İzleyin

    The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a r

    OrtaCVSS 4,3İstismar yokEPSS %3

    trustwave · modsecurity3 Haz 2009

  • CVE-2009-5031
    18İzleyin

    ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filteri

    OrtaCVSS 4,3İstismar yokEPSS %3

    trustwave · modsecurity22 Tem 2012